2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-38458HIGH8.8Xenforo before 2.2.16 allows code injection.
CVE-2024-38457HIGH8.8Xenforo before 2.2.16 allows CSRF.
CVE-2024-38454MEDIUM6.1ExpressionEngine before 7.4.11 allows XSS.
CVE-2024-38448CRITICAL9.1htags in GNU Global through 6.6.12 allows code execution in situations where dbpath (aka -d) is untrusted, because shell...
CVE-2024-38443MEDIUM6.2C/sorting/binary_insertion_sort.c in The Algorithms - C through e5dad3f has a segmentation fault for deep recursion, whi...
CVE-2024-38441CRITICAL9.8Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[len] to '...
CVE-2024-38440HIGH7.5Netatalk before 3.2.1 has an off-by-one error, and resultant heap-based buffer overflow and segmentation violation, beca...
CVE-2024-38439CRITICAL9.8Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[PASSWDLEN...
CVE-2024-36397MEDIUM6.1Vantiva - MediaAccess DGA2232 v19.4 - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site S...
CVE-2024-38428CRITICAL9.1url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be inse...
CVE-2024-38427HIGH8.8In International Color Consortium DemoIccMAX before 85ce74e, a logic flaw in CIccTagXmlProfileSequenceId::ParseXml in Ic...
CVE-2024-38395CRITICAL9.8In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution mi...
CVE-2024-38394MEDIUM4.3Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kerne...
CVE-2024-6016CRITICAL9.8A vulnerability, which was classified as critical, has been found in itsourcecode Online Laundry Management System 1.0. ...
CVE-2024-6015CRITICAL9.8A vulnerability classified as critical was found in itsourcecode Online House Rental System 1.0. Affected by this vulner...
CVE-2024-6014CRITICAL9.8A vulnerability classified as critical has been found in itsourcecode Document Management System 1.0. Affected is an unk...
CVE-2024-6013CRITICAL9.8A vulnerability was found in itsourcecode Online Book Store 1.0. It has been rated as critical. This issue affects some ...
CVE-2024-6009CRITICAL9.8A vulnerability has been found in itsourcecode Event Calendar 1.0 and classified as critical. Affected by this vulnerabi...
CVE-2024-6008HIGH8.8A vulnerability, which was classified as critical, was found in itsourcecode Online Book Store up to 1.0. Affected is an...
CVE-2024-31870LOW3.3IBM Db2 for i 7.2, 7.3, 7.4, and 7.5 supplies user defined table function is vulnerable to user enumeration by a local a...
CVE-2024-27275HIGH7.8IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an insufficient authority req...
CVE-2024-6007CRITICAL9.8A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3. This affects...
CVE-2024-6006LOW3.5A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been rated as problematic. Affected by this iss...
CVE-2024-6005LOW3.5A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been declared as problematic. Affected by this ...
CVE-2024-5611MEDIUM6.4The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘label_years’ ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now